Skip to content

v0.1.0

Choose a tag to compare

@fstubner fstubner released this 30 Jun 11:23

nvx v0.1.0 — Initial Stable Release

nvx (Node Version X-platform) is a zero-dependency, ultra-fast, and security-conscious runtime version manager and package manager wrapper. It is designed to secure local developer environments, AI coding agents, and CI/CD runners against supply-chain attacks while maintaining native-speed execution.

Backstory: Why nvx?

This project started while setting up a clean development machine on Windows. Facing the usual version manager headaches (aliases failing in IDEs, slow startup times, environment leaks across concurrent terminals), I decided to build a modern, native runtime version manager from scratch to solve these issues.

Why Go?

I chose Go as the implementation language for several key reasons:

  1. Zero-Dependency Native Binaries: Go compiles to a single, zero-dependency binary with sub-millisecond execution overhead. It requires no interpreter (like Python) or runtime environment (like Node.js itself) to execute.
  2. First-Class Platform Interoperability: Go allowed me to easily interface with platform-specific security primitives—such as Windows Low Integrity Level tokens and native Linux Namespaces—while keeping the codebase clean and maintainable.
  3. Cross-Platform by Design: A single codebase compiles cleanly to target Windows, macOS, and Linux (amd64/arm64) natively.

Core Security Drivers

Along the way, I designed nvx to solve two major security concerns in modern development:

  • Supply Chain Safety: Typosquatting and malicious pre/postinstall hooks are active threats. nvx intercepts installs on the fly to scan, check, and control package executions.
  • AI Coding Agent Safety: AI agents (like Gemini, Claude, or Copilot) executing shell commands in your workspace present a new risk. By automatically wrapping package managers and runners, nvx guarantees that any package an AI agent attempts to install or run is audited and sandboxed automatically, reducing workspace compromise risks.

Key Features in v0.1.0

  • Multi-Platform Runtime Version Swapping: Swaps Node.js versions in under a millisecond by modifying only session-level shell environment variables (PATH, NPM_CONFIG_PREFIX), supporting PowerShell, Zsh, and Bash.
  • Auto-Configuration Swapping: Instantly switches Node.js version when navigating into directories containing configuration files (.nvmrc, .node-version, package.json, or Volta configurations).
  • Dynamic PATH Shim Architecture: Uses dynamic shims in ~/.nvx/bin to intercept execution reliably in subshells, IDEs, and scripts, resolving early shell alias vulnerabilities.
  • Registry Checksum Integrity: Enforces cryptographic integrity for Node.js downloads using SHA-256 hashes from nodejs.org, mitigating MITM or server compromise attacks.
  • Interactive Security Interceptor: Intercepts npm, yarn, and pnpm install commands to perform:
    • Vulnerability scans against the OSV database.
    • Typosquatting audits based on Levenshtein distance and registry download comparison.
    • Release-age warning for packages published less than 24 hours ago.
    • Install script blocking/warning to prevent arbitrary code execution during dependencies installation.
  • Process Sandboxing: Runs executions inside isolated environments: either using OS-native isolation primitives (Windows Low Integrity Levels and Linux Namespaces with home directory virtualization and environment scrubbing) or containerized via Docker.

Upcoming Features in v0.2.0 (Roadmap)

I am actively working on the next set of features to make nvx even more secure and robust:

  • Secret Interception: In-memory resolution of credentials (e.g. op:// 1Password and aws:// secrets) before sandboxed execution to keep credentials entirely out of workspace configuration files.
  • Workspace Write Protection: Copy-on-Write (CoW) sandbox environments to emulate a read-only local workspace, symlinking only safe assets and preventing unauthorized writes.
  • Native Multi-OS Sandbox Engines: Expanding native sandboxing options to support:
    • macOS native sandboxing via sandbox-exec using Scheme profiles.
    • Windows WSL Containers (wslc) natively without requiring Docker Desktop.
    • Linux container runtimes natively via systemd-nspawn.

Quick Start Installation

Windows (PowerShell)

irm https://raw.githubusercontent.com/fstubner/nvx/master/install.ps1 | iex

macOS / Linux (Shell)

curl -fsSL https://raw.githubusercontent.com/fstubner/nvx/master/install.sh | sh